DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

More additions to HHS's breach tool

Posted on May 21, 2013 by Dissent

Two updates within a week? The HHS breach tool is getting a workout.  Here is what was added today:

Sovereign Medical Group, LLC in New Jersey reported that 27,800 were affected by a breach on October 10, 2012. HHS’s breach tool codes the incident as “Theft, Hacking/IT Incident”, Network Server,” which probably means a hack, but I’ve found no media coverage of this breach and have sent them an inquiry.

South Jersey Hospital Inc. disclosed in January that they were affected by the Omnicell breach reported previously on this blog. Why their report to HHS is first appearing on HHS’s breach tool is unclear to me: were they late in notifying HHS, or did HHS delay posting this while they investigated? HHS has informed me in the past that they do not add incidents to the breach tool until they’ve done a preliminary verification of certain details. Looking at the other entries in this latest batch, my guess is that HHS delayed posting these incidents while they investigated.

Hawaii State Department of Health, Adult Mental Health Division disclosed a breach in October 2012 that is also first appearing on HHS’s breach tool. According to the entry, 674 clients were affected by a hack that occurred on September 25, 2012.

L.A. Care Health Plan in California reported that 18,000, were affected by an unspecified breach that occurred between September 17 and September 20, 2012. That breach had previously been reported on this blog and involved a mailing error that sent members’ IDs to the wrong addresses.

Calvin Schuster, MD of California reported that 532 patients had data on a computer stolen November 14, 2012. That breach was previously reported on this blog. Somewhat confusingly – or perhaps it’s a typo on HHS’s tool or in the doctor’s letter to patients – the log entry shows the theft occurred on November 14, while Dr. Schuster’s letter to patients says they learned of the breach on November 5.

SilverScript Insurance Company in Arizona, a CVS Caremark company and Medicare Part D Plan insurer, reported a breach affecting 852 patients on October 31, 2012. That breach involved paper records,  and might be a mailing error, but I can find no documentation of this breach available online.

Raleigh Orthopaedic Clinic in North Carolina’s breach affecting 17,300 patients was also added to the breach tool. That incident, involving stolen x-rays, was previously reported on this blog.

Category: Health Data

Post navigation

← NYPD detective charged with hacking
Idaho State University Settles HIPAA Security Case for $400,000 →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Washington Post investigating cyberattack on journalists, WSJ reports
  • Resource: State Data Breach Notification Laws – June 2025
  • WestJet investigates cyberattack disrupting internal systems
  • Plastic surgeons often store nude photos of patients with their identity information. When would we call that “negligent?”
  • India: Servers of two city hospitals hacked; police register FIR
  • Ph: Coop Hospital confirms probe into reported cyberattack
  • Slapped wrists for Financial Conduct Authority staff who emailed work data home
  • School Districts Unaware BoardDocs Software Published Their Private Files
  • A guilty plea in the PowerSchool case still leaves unanswered questions
  • Brussels Parliament hit by cyber-attack

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Vermont signs Kids Code into law, faces legal challenges
  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation
  • Anne Wojcicki Wins Bidding for 23andMe
  • Would you — or wouldn’t you?
  • New York passes a bill to prevent AI-fueled disasters
  • Synthetic Data and the Illusion of Privacy: Legal Risks of Using De-Identified AI Training Sets
  • States sue to block the sale of genetic data collected by DNA testing company 23andMe

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.